<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Embedding Sense client in iframe yields authentication problem with Azure according to header X-Frame-Options = deny in Integration, Extension &amp; APIs</title>
    <link>https://community.qlik.com/t5/Integration-Extension-APIs/Embedding-Sense-client-in-iframe-yields-authentication-problem/m-p/2420625#M19940</link>
    <description>&lt;P&gt;&lt;SPAN class="message-body-wrapper"&gt;&lt;SPAN class="message-flex-body"&gt;&lt;SPAN class="message-body devtools-monospace"&gt;&lt;SPAN class="objectBox objectBox-string"&gt;Trying to embed a Sense app into an iframe in a web app, but getting issues from Microsoft Azure AD (which is the IDP for the Qlik Cloud tenant). It seems that when the frame gets redirected to Azure for authentication, that in turn disallows embed, and so it fails to render.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="message-body-wrapper"&gt;&lt;SPAN class="message-flex-body"&gt;&lt;SPAN class="message-body devtools-monospace"&gt;&lt;SPAN class="objectBox objectBox-string"&gt;"The loading of “&lt;A class="url" title="https://login.microsoftonline.com/34343572-9156-4f33-bf0e-d5c10f1d8165/oauth2/v2.0/authorize?client_id=070a28a1-15fc-4dff-a964-609be0220d51&amp;amp;scope=openid%20profile%20email&amp;amp;response_type=code&amp;amp;redirect_uri=https%3A%2F%2Fxh6tp5ddg8ao1nj.eu.qlikcloud.com%2Flogin%2Fcallback&amp;amp;state=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdHIiOjEsInN0aWQiOiIydGdPR1ZyRV8zS1pjNy1wdklHTDVqXzk3VGJRX2ZsdmpxV2FlWC1kYVlrIiwiaWF0IjoxNzA4MzM1MDA3LCJleHAiOjE3MDg5Mzk4MDd9.5Ut3L2wMmXVHe_3Jlg5_4io7YCt5Oz06tlW-ZN-E7aQ&amp;amp;nonce=s_OKm7VjPUdpynDbkoWmyu9UA2K22x501fBm5d3aLlg&amp;amp;code_challenge=efGNemTqe7NRts4Wjuns4zpxvqqdXFy1mh2zIxMLb1o&amp;amp;code_challenge_method=S256" draggable="false" href="https://login.microsoftonline.com/34343572-9156-4f33-bf0e-d5c10f1d8165/oauth2/v2.0/authorize?client_id=070a28a1-15fc-4dff-a964-609be0220d51&amp;amp;scope=openid%20profile%20email&amp;amp;response_type=code&amp;amp;redirect_uri=https%3A%2F%2Fxh6tp5ddg8ao1nj.eu.qlikcloud.com%2Flogin%2Fcallback&amp;amp;state=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdHIiOjEsInN0aWQiOiIydGdPR1ZyRV8zS1pjNy1wdklHTDVqXzk3VGJRX2ZsdmpxV2FlWC1kYVlrIiwiaWF0IjoxNzA4MzM1MDA3LCJleHAiOjE3MDg5Mzk4MDd9.5Ut3L2wMmXVHe_3Jlg5_4io7YCt5Oz06tlW-ZN-E7aQ&amp;amp;nonce=s_OKm7VjPUdpynDbkoWmyu9UA2K22x501fBm5d3aLlg&amp;amp;code_challenge=efGNemTqe7NRts4Wjuns4zpxvqqdXFy1mh2zIxMLb1o&amp;amp;code_challenge_method=S256" target="_blank" rel="noopener noreferrer"&gt;https://login.microsoftonline.com/REDACTED&lt;/A&gt;” in a frame is denied by “X-Frame-Options“ directive set to “deny“."&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="message-body-wrapper"&gt;&lt;SPAN class="message-flex-body"&gt;&lt;SPAN class="message-body devtools-monospace"&gt;&lt;SPAN class="objectBox objectBox-string"&gt;Can we pre-auth the browser somehow with javascript to not have this redirect happen? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Feb 2024 09:47:47 GMT</pubDate>
    <dc:creator>StefanBackstrand</dc:creator>
    <dc:date>2024-02-19T09:47:47Z</dc:date>
    <item>
      <title>Embedding Sense client in iframe yields authentication problem with Azure according to header X-Frame-Options = deny</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/Embedding-Sense-client-in-iframe-yields-authentication-problem/m-p/2420625#M19940</link>
      <description>&lt;P&gt;&lt;SPAN class="message-body-wrapper"&gt;&lt;SPAN class="message-flex-body"&gt;&lt;SPAN class="message-body devtools-monospace"&gt;&lt;SPAN class="objectBox objectBox-string"&gt;Trying to embed a Sense app into an iframe in a web app, but getting issues from Microsoft Azure AD (which is the IDP for the Qlik Cloud tenant). It seems that when the frame gets redirected to Azure for authentication, that in turn disallows embed, and so it fails to render.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="message-body-wrapper"&gt;&lt;SPAN class="message-flex-body"&gt;&lt;SPAN class="message-body devtools-monospace"&gt;&lt;SPAN class="objectBox objectBox-string"&gt;"The loading of “&lt;A class="url" title="https://login.microsoftonline.com/34343572-9156-4f33-bf0e-d5c10f1d8165/oauth2/v2.0/authorize?client_id=070a28a1-15fc-4dff-a964-609be0220d51&amp;amp;scope=openid%20profile%20email&amp;amp;response_type=code&amp;amp;redirect_uri=https%3A%2F%2Fxh6tp5ddg8ao1nj.eu.qlikcloud.com%2Flogin%2Fcallback&amp;amp;state=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdHIiOjEsInN0aWQiOiIydGdPR1ZyRV8zS1pjNy1wdklHTDVqXzk3VGJRX2ZsdmpxV2FlWC1kYVlrIiwiaWF0IjoxNzA4MzM1MDA3LCJleHAiOjE3MDg5Mzk4MDd9.5Ut3L2wMmXVHe_3Jlg5_4io7YCt5Oz06tlW-ZN-E7aQ&amp;amp;nonce=s_OKm7VjPUdpynDbkoWmyu9UA2K22x501fBm5d3aLlg&amp;amp;code_challenge=efGNemTqe7NRts4Wjuns4zpxvqqdXFy1mh2zIxMLb1o&amp;amp;code_challenge_method=S256" draggable="false" href="https://login.microsoftonline.com/34343572-9156-4f33-bf0e-d5c10f1d8165/oauth2/v2.0/authorize?client_id=070a28a1-15fc-4dff-a964-609be0220d51&amp;amp;scope=openid%20profile%20email&amp;amp;response_type=code&amp;amp;redirect_uri=https%3A%2F%2Fxh6tp5ddg8ao1nj.eu.qlikcloud.com%2Flogin%2Fcallback&amp;amp;state=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdHIiOjEsInN0aWQiOiIydGdPR1ZyRV8zS1pjNy1wdklHTDVqXzk3VGJRX2ZsdmpxV2FlWC1kYVlrIiwiaWF0IjoxNzA4MzM1MDA3LCJleHAiOjE3MDg5Mzk4MDd9.5Ut3L2wMmXVHe_3Jlg5_4io7YCt5Oz06tlW-ZN-E7aQ&amp;amp;nonce=s_OKm7VjPUdpynDbkoWmyu9UA2K22x501fBm5d3aLlg&amp;amp;code_challenge=efGNemTqe7NRts4Wjuns4zpxvqqdXFy1mh2zIxMLb1o&amp;amp;code_challenge_method=S256" target="_blank" rel="noopener noreferrer"&gt;https://login.microsoftonline.com/REDACTED&lt;/A&gt;” in a frame is denied by “X-Frame-Options“ directive set to “deny“."&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="message-body-wrapper"&gt;&lt;SPAN class="message-flex-body"&gt;&lt;SPAN class="message-body devtools-monospace"&gt;&lt;SPAN class="objectBox objectBox-string"&gt;Can we pre-auth the browser somehow with javascript to not have this redirect happen? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2024 09:47:47 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/Embedding-Sense-client-in-iframe-yields-authentication-problem/m-p/2420625#M19940</guid>
      <dc:creator>StefanBackstrand</dc:creator>
      <dc:date>2024-02-19T09:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Embedding Sense client in iframe yields authentication problem with Azure according to header X-Frame-Options = deny</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/Embedding-Sense-client-in-iframe-yields-authentication-problem/m-p/2421323#M19960</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/14150"&gt;@StefanBackstrand&lt;/a&gt;&amp;nbsp;- absolutely!&lt;/P&gt;
&lt;P&gt;Here's a &lt;A href="https://qlik.dev/embed/qlik-embed/" target="_blank" rel="noopener"&gt;forward looking framework&lt;/A&gt;, and here are some&lt;A href="https://qlik.dev/embed/iframe/" target="_blank" rel="noopener"&gt; iFrame specific examples&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 15:53:50 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/Embedding-Sense-client-in-iframe-yields-authentication-problem/m-p/2421323#M19960</guid>
      <dc:creator>jprdonnelly</dc:creator>
      <dc:date>2024-02-20T15:53:50Z</dc:date>
    </item>
  </channel>
</rss>

